PatchSiren

Joomla! Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Joomla! Project CVE published 2026-08-18

CVE-2026-73372

The Joomla! Core has an improper access check that injects contact information for unaccessible contact items into schema.org snippets. This issue affects Joomla! Core versions 5.1.0-5.4.7 and 6.0.0-6.1.2. The vulnerability is caused by inadequate access controls, allowing unauthorized data injection. Users should review and apply updates to prevent potential exploitation. The vulnerability has a CVSS sco [truncated]

MEDIUM Joomla! Project CVE published 2026-08-18

CVE-2026-72531

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T17:17:02.477Z and has not been modified since then. The NVD entry is currently Analyzed. Joomla! Core versions 4.0.0-5.4.7, 6.0.0-6.1.2 are affected by Improper ACL checks for custom fields webservice endpoints vulnerability. This vulnerability allows unauthorized users to create fields for inacc [truncated]

MEDIUM Joomla! Project CVE published 2026-08-18

CVE-2026-71573

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T17:17:02.243Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability affects Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2, allowing attackers to perform unauthorized actions on behalf of users due to improper CORS origin validation. This issue has a CVSS [truncated]

MEDIUM Joomla! Project CVE published 2026-08-18

CVE-2026-71572

The CVE-2026-71572 vulnerability in Joomla! Core download views allows for reflected file download and content-type confusion due to a lack of output processing, enabling header injection. This issue affects Joomla versions 3.0.0-5.4.7 and 6.0.0-6.1.2, with a CVSS score of 4.8 and a Medium severity level. The vulnerability can be exploited through specially crafted requests, potentially leading to securit [truncated]

HIGH Joomla! Project CVE published 2026-08-18

CVE-2026-73373

The CVE-2026-73373 vulnerability is an unrestricted upload of SHTML files in Joomla! Core versions 1.0.0-5.4.7 and 6.0.0-6.1.2. This vulnerability allows for code execution on servers that execute these files due to SHTML files not being included in the default list of dangerous files. Administrators and users of affected versions should be aware of this vulnerability and take necessary actions to protect [truncated]

HIGH Joomla! Project CVE published 2026-08-18

CVE-2026-73337

CVE-2026-73337 is a high-severity vulnerability in Joomla! Core, affecting versions 4.0.0-5.4.7 and 6.0.0-6.1.2. The vulnerability allows for MFA authentication bypass due to insufficient state checks. This issue impacts organizations using Joomla! Core, as it could allow attackers to bypass 2FA checks, potentially leading to unauthorized access. Defenders and administrators should assess exposure and pri [truncated]

HIGH Joomla! Project CVE published 2026-08-18

CVE-2026-71574

CVE-2026-71574 is a HIGH-rated vulnerability in Joomla! Core affecting versions 4.0.0-5.4.7 and 6.0.0-6.1.2. An improper access check allows unauthorized users to perform mutation actions in webservice endpoints. The vulnerability is tracked by CWE-284. This issue was published on 2026-08-18T16:18:16.457Z and has not been modified since then. The NVD entry is currently Analyzed. Joomla users and administr [truncated]

MEDIUM Joomla! Project CVE published 2026-08-18

CVE-2026-73336

A PatchSiren debrief of CVE-2026-73336, an XSS vulnerability through schema.org outputs in Joomla! CMS versions 5.1.0-5.4.7 and 6.0.0-6.1.2. This vulnerability arises from improper escaping flags leading to an XSS vector in schema.org markup outputs. Defenders should assess exposure and prioritize remediation, focusing on verifying and remediating this vulnerability to prevent potential XSS attacks. The C [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48958

CVE-2026-48958 is a medium-severity vulnerability allowing unauthorized users to create custom fields via webservices endpoints due to an improper access check. The CVE record was published on 2026-07-07T19:16:54.567Z and has not been modified since then. This vulnerability affects Joomla installations and is classified under CWE-284, with a CVSS score of 6.4. Security teams and administrators should asse [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48957

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-07T19:16:54.440Z and has not been modified since then. This medium-severity vulnerability with a CVSS score of 6.4 involves an improper access check that allows unauthorized users to access com_privacy datasets in Joomla. Security teams should verify if their Joomla installations are affected by thi [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48956

CVE-2026-48956 is a medium-severity vulnerability with a CVSS score of 6.4. An improper access check allows users to display a list of modules in the frontend. The CVE record was published on 2026-07-07T19:16:54.313Z and has not been modified since then. This vulnerability could potentially lead to unauthorized access to sensitive information. Administrators and users of Joomla systems should be aware of [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48955

CVE-2026-48955 is a medium-severity vulnerability in Joomla that allows unauthorized users to access workflow stage and transition information due to an improper access check. The vulnerability has a CVSS score of 6.4 and is classified as CWE-284. It affects Joomla deployments, and users with administrative privileges should be aware of this vulnerability and take necessary precautions to prevent unauthor [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48954

CVE-2026-48954 is a medium-severity vulnerability related to improper validation leading to a generic XSS vector in the language override feature of Joomla. The CVE record was published on 2026-07-07T19:16:54.060Z and has not been modified since then. The NVD entry is currently Received. This vulnerability affects Joomla installations and requires immediate attention to prevent potential attacks. Users sh [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48952

CVE-2026-48952 is a MEDIUM severity vulnerability with a CVSS score of 5.9, caused by a lack of escaping leading to an XSS vulnerability in the update list view of com_installer. Administrators and users of Joomla should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-07-07T19:16:53.810Z and has not been modified since then. The vulnerability [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48951

CVE-2026-48951 is a MEDIUM severity vulnerability with a CVSS score of 5.9. The vulnerability is caused by a lack of escaping, leading to XSS vulnerabilities in modalreturn layouts of various components. This vulnerability affects users of Joomla and could lead to XSS attacks if not patched. The CVE record was published on 2026-07-07T19:16:53.680Z and has not been modified since then.

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48950

A vulnerability exists in com_templates due to a lack of escaping, leading to a cross-site scripting (XSS) vulnerability in the file management view. The CVE record was published on 2026-07-07T19:16:53.543Z and has not been modified since then. This vulnerability affects Joomla users and administrators, who should be aware of this issue and take necessary precautions to prevent exploitation. The vulnerabi [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48949

A vulnerability CVE-2026-48949 was found in an unknown vendor's product. The vulnerability has a CVSS score of 5.9 and is classified as MEDIUM. It is caused by a lack of validation leading to an XSS vulnerability in the MFA management views. Security teams should review and validate input data for MFA management views to prevent potential XSS attacks. The CVE record was published on 2026-07-07T19:16:53.20 [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48948

CVE-2026-48948 is a medium-severity vulnerability in Joomla's com_contact component. An improper access check allows users to download vCard exports of com_contact contacts that are inaccessible. The CVE record was published on 2026-07-07T19:16:52.800Z and has not been modified since then. This vulnerability could potentially be used to access sensitive contact information. Administrators and users of Joo [truncated]

MEDIUM Joomla! Project CVE published 2026-07-07

CVE-2026-48947

CVE-2026-48947 is a medium-severity vulnerability allowing privileged users to overwrite media files without editing permissions. The CVE record was published on 2026-07-07T19:16:52.607Z and has not been modified since then. This improper access control vulnerability, reported in Joomla, has a CVSS score of 6.4. Affected administrators and users with privileged access to media management systems should as [truncated]

MEDIUM Joomla! Project CVE published 2026-05-26

CVE-2026-48905

A cross-site scripting (XSS) vulnerability exists in Joomla! due to inadequate input filtering within the HTML filter's cleanAttributes code. The flaw allows attackers with high privileges to inject malicious scripts through insufficiently sanitized content, potentially compromising user sessions or executing unauthorized actions in victims' browsers. The vulnerability affects Joomla! versions 3.0.0 throu [truncated]

HIGH Joomla! Project CVE published 2026-05-26

CVE-2026-48904

A privilege escalation vulnerability exists in Joomla's com_users component, specifically within the group editing webservice endpoint. The improper access check allows unauthenticated or lower-privileged actors to escalate privileges by manipulating group assignments through the webservice API. The vulnerability affects Joomla 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The CVSS 4.0 vector indicates net [truncated]

MEDIUM Joomla! Project CVE published 2026-05-26

CVE-2026-48903

A cross-site scripting (XSS) vulnerability exists in Joomla! Framework due to inadequate content filtering within the checkAttribute methods. The flaw affects Joomla! versions from 3.0.0 through 5.4.5 and from 6.0.0 through 6.1.0. An attacker with high privileges can exploit this vulnerability to inject malicious scripts, potentially compromising user sessions or performing unauthorized actions. The CVSS [truncated]

CRITICAL Joomla! Project CVE published 2026-05-26

CVE-2026-48902

## Summary CVE-2026-48902 describes a transport-layer security downgrade in Joomla's password and username reset functionality. When the application generates reset links, it produces plain HTTP URLs even for HTTPS connections unless an administrator has explicitly enabled the

HIGH Joomla! Project CVE published 2026-05-26

CVE-2026-48901

CVE-2026-48901 describes a vulnerability in the `InputFilter::getInstance()` method where a security-sensitive parameter was omitted from the instance cache key construction. This flaw could allow improper cache reuse across different security contexts, potentially leading to security boundary violations in input filtering operations. The vulnerability was published on 2026-05-26 and is currently undergoi [truncated]

MEDIUM Joomla! Project CVE published 2026-05-26

CVE-2026-48900

A medium-severity improper access control vulnerability in Joomla's scheduler component (com_scheduler) allows low-privileged users to modify task types of existing scheduled tasks. The flaw stems from incorrect access checks in the task type editing functionality. Affected versions include Joomla 4.1.0 through 5.4.5 and 6.0.0 through 6.1.0. The vulnerability was disclosed by Joomla's security team on May [truncated]

MEDIUM Joomla! Project CVE published 2026-05-26

CVE-2026-48899

A medium-severity improper access control vulnerability in Joomla's com_users batch task allows authenticated users with limited privileges to escalate their permissions. The flaw exists in the sample data plugins component where access checks are incorrectly implemented during batch operations. Joomla versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0 are affected. The vulnerability was disclosed by th [truncated]

HIGH Joomla! Project CVE published 2026-05-26

CVE-2026-48898

An improper access control vulnerability in Joomla's com_users batch task allows unauthenticated attackers to escalate privileges. The flaw exists in the batch processing functionality of the user management component, where missing authorization checks permit unauthorized privilege modifications. Affected versions include Joomla 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The vulnerability was disclosed [truncated]

HIGH Joomla! Project CVE published 2026-05-26

CVE-2026-48897

A high-severity authentication bypass vulnerability in Joomla Core allows attackers to circumvent multi-factor authentication (MFA) checks due to insufficient state validation. The flaw, published 2026-05-26, carries a CVSS 4.0 score of 8.2 (HIGH severity) with a vector indicating network attack vector, low attack complexity, no privileges required, and high impact to integrity. The vulnerability stems fr [truncated]

HIGH Joomla! Project CVE published 2026-05-26

CVE-2026-48896

CVE-2026-48896 is a HIGH severity vulnerability (CVSS 8.2) in Joomla! Core related to insufficient state checks that enable two-factor authentication (2FA) bypass. The vulnerability was published on 2026-05-26 and is currently undergoing analysis by NVD. The issue stems from improper authentication (CWE-287) where state validation failures allow attackers to circumvent MFA protections. Joomla! has publish [truncated]

MEDIUM Joomla! Project CVE published 2026-05-26

CVE-2026-40384

A path traversal vulnerability exists in the com_media files API endpoint due to improper validation of the search parameter. The vulnerability allows an attacker with high privileges to read arbitrary files on the system. The issue is rated MEDIUM severity with a CVSS score of 5.9. The vulnerability was disclosed by the Joomla! Security Strike Team and affects Joomla! CMS core. The weakness is classified [truncated]